The whole setup is two files you already have, sent through a browser. Nothing is installed on your side, nothing writes back into your systems, and the files you send are purged thirty days after your deliverables land.
Accepted: PDF, CSV, XLSX · up to 12 files and 25 MB per upload
None
No key to your ERP, your buyer portals or your mailbox. Nothing for your security team to provision, rotate or revoke.
None
No agent, no scheduled job, no software on your network. There is one route that accepts a file and it is an upload box.
None
Axiom reads what you send and returns files. No system of yours is modified, so there is no rollback to plan for.
None
We never email a buyer and never log into a portal on your behalf. Whatever goes out, goes out from you.
None
Your documents are read to be audited and for nothing else. They are not retained as training data at any point.
One gate cut into one perimeter, two files through it, and no line drawn back the other way. The clock underneath runs from the moment your work product lands to the moment what you sent is gone.
2
Files you send
3
Accepted formats
25 MB
Per request, all files
30 d
From delivery to purge
One CSV or XLSX with every invoice, what was billed, what arrived, and the deduction reason or code. Title rows, merged cells and parenthesised negatives are expected, not something to clean up first.
One governing agreement. Read page by page with character offsets kept, so a quoted clause resolves to a page in your document rather than to a document in general.
It runs on a schedule inside the database rather than on somebody’s laptop, and the date it reads is stamped by the same event that delivers your work product. Deletion is not a request you have to file.
Built so finance and AR operations can run the first audit without waiting on an engineering backlog, and without reformatting a spreadsheet first.
The leading bytes of a file say what it is; the extension only has to agree. Renaming an executable to .csv does not get it past the door.
PDF active content, spreadsheet macros, OLE objects, embedded executables and DDE formulas are all rejected at intake. Our own scan, not an antivirus engine — and we say so.
The header row is located under whatever preamble your report generator added, merged cells are unmerged, and a column that cannot be matched is reported back rather than dropped.
Row-level security on every table, with the organisation stamped on each row and composite keys making a cross-tenant reference unrepresentable. Not a filter in application code.
Axiom holds no compliance certification and claims none. What we can offer instead is a walkthrough of exactly how each control above works, in the code.
The documents you upload exist to be audited, not kept. Thirty days after your deliverables land, the intake files are purged on schedule.
The AR export of the short-paid lines, and the signed agreement that priced them. No connector to install, no key to issue, nothing for your IT group to schedule — and the files you send are purged thirty days after your deliverables land.